Re: [PATCH 0/4] faster SHA-1 collision detection
- From
Junio C Hamano <gitster@pobox.com>
- Date
- Oct 9, 2026, 23:41 UTC
- Message-ID
- <xmqq7bjqjvbi.fsf@gitster.g>
- In-Reply-To
- <CALnO6CBbtKomawqc81MPV5Ngtc9J3M1ej4enGD3ZUzWnPSfsgw@mail.gmail.com>
"D. Ben Knoble" <ben.knoble@gmail.com> writes:
Show 23 quoted lines
> The sha1collisiondetection submodule and the sha1dc code (extracted > from that submodule's upstream, if I'm reading 28dc98e343 (sha1dc: add > collision-detecting sha1 implementation, 2017-03-16) correctly?) are > MIT licensed, too, so there is some precedent for Git here. I skimmed > what I could find of the original threads: > > - https://lore.kernel.org/git/20170223195753.ppsat2gwd3jq22by@sigill.intra.peff.net/ > - https://lore.kernel.org/git/?q=sha1dc%3A+add+collision-detecting+sha1+implementation > > but I didn't see a discussion of licensing at that time. Perhaps the > idea is that we are clear that such code carries a different license > from Git? > > Anyway, I suppose the fair thing would then be for Scott's code to be > MIT (and/or Apache2), in which case it would need similar > clarifications? (Or are we prepared to take the stance that de nouveau > code based on existing code can be license-washed, in this case to > GPL-2?) > > Interestingly, Gentoo claims Git's license is only GPL-2, but I think > they compile in the sha1dc code since it's the default in meson. > Should we be claiming the Git package (with sha1dc) is actually GPL-2 > and MIT?
In the abov, Gentoo's mention is about "Git package" as a whole. Git package as a whole can be distributed under GPLv2 only.
MIT, BSD-2 or BSD-3 are permissive and essentially says "you can do whatever you want with the code (including combining with other code or making it proprietary), as long as you keep our copyright notice, keep our disclaimer, and (in the case of BSD-3) do not use our names for endorsement". Specifically, they do not forbid us from incorporating their ware into our project that is licensed differently, as long as we honor their licensing terms on the source files we got from them.
Because we have mixed "permissive" code into GPLv2 code to form a single "work based on the Program", GPLv2 Section 2(b) dictates that the entire combined work must be distributed under the terms of the GPLv2 (and again, the permissiveness of "other" licenses is what allows us to do so). You cannot distribute the finished binary or the combined sources under a permissive license, because doing so would violate the GPLv2's copyleft requirement.
The original "permissively licensed" files (and any modifications made purely to those files) still maintain their original copyright headers and original "permissive" license text. This is because the original copyright holder of the code granted a license to use their files under the original "permissive" licensing terms, which requires us to keep their copyright notice. We do not own the copyright to the original "permissive" code. We are only licensed to use them. So we have no legal authority to strip these "permissive" licenses or unilaterally "relicense" those files into GPLv2.
So to answer your question in the last sentence, we should say "Git package as a whole is GPLv2 only, but parts are borrowed from copyright holders who licensed them under different terms, and these parts can be used under these different parts. For example, sha1dc can be copied from our source tree to your non GPLv2 project as long as you honor their MIT license".